System and method for performing a transaction
Abstract
A system for performing a transaction comprises a terminal adapted to perform a transaction required by a user, user authentication means and a transaction server adapted to communicate with the terminal. The user authentication means comprise a first and a second authentication device adapted to communicate with the terminal through respectively a first communication channel and second communication channel and comprise storage means for storing respective first and second user authentication keys. The transaction server comprises storage means for storing, for each of the authentication devices, respective first and second server authentication keys. In particular, the first authentication keys are distinct from the second authentication keys.
Claims
exact text as granted — not AI-modified1 . System for performing a transaction comprising:
a terminal adapted to perform a transaction required by a user and identified by a plurality of transaction identification codes, user authentication means adapted to communicate with said terminal and associated to a user identification code, a transaction server adapted to communicate with said terminal,
wherein
said terminal comprises first communication means adapted to communicate through a first communication channel and second communication means adapted to communicate through a second communication channel,
said user authentication means comprise a first and a second authentication device adapted to communicate with said terminal through respectively said first communication channel and said second communication channel and comprising storage means for storing respective first and second user authentication keys,
said transaction server comprises storage means for storing, for said first and second authentication devices, respectively first and second server authentication keys,
said first authentication keys are distinct from said second authentication keys.
2 . System according to claim 1 , wherein each of said first and second authentication devices and transaction server comprises computing means for generating authentication codes in function of the authentication keys stored in the respective storage means and of said plurality of transaction identification codes.
3 . System according to claim 1 , wherein for at least one of said first and second authentication devices, the authentication keys are symmetric keys and are stored in association to a user identification code,
said server and said at least one authentication device are adapted to elaborate said plurality of transaction identification codes and the respective authentication keys associated to said user identification code for generating and sending to said terminal respective authentication codes for the authentication of the server to said at least one user authentication device and of said at least one user authentication device to the server.
4 . System according to claim 3 , wherein said terminal comprises computing means for comparing the authentication codes generated and sent by the server and by said at least one user authentication device.
5 . System according to claim 3 , comprising a plurality of transaction servers, each transaction server being associated to a server identification code, the storage means of the user authentication devices comprise, for each server identification code, respective first and second user authentication keys.
6 . System according to claim 4 , wherein the terminal is adapted to identify and send to said two user authentication devices said server identification code, said authentication devices being adapted to extract from the respective storage means the first and the second user authentication keys associated to said server identification code sent by the terminal.
7 . System according to claim 3 , wherein, for both said first and second authentication devices, the authentication keys are symmetric keys and are stored in association to a user identification code.
8 . System according to claim 1 , wherein, for at least one of said first or second user authentication device, the authentication keys are asymmetric keys,
said transaction server and said at least one user authentication device are adapted to elaborate said plurality of transaction identification codes and the respective authentication keys for generating and sending, through said terminal, respectively to said at least one user authentication device and said transaction server respective authentication codes for the authentication of the server to the user authentication device and of the user authentication device to the server.
9 . System according to claim 8 , wherein, for both said first and second user authentication devices, the authentication keys are asymmetric keys.
10 . System according to claim 1 , wherein said terminal communicates, in sequence, with the first user authentication device through said first communication channel and, subsequently, with the second authentication device through said second communication channel.
11 . System according to claim 1 , wherein said first user authentication device comprises a mobile terminal and said second user authentication device comprises an rfid tag.
12 . Method for performing a transaction in a system comprising:
a terminal adapted to communicate through a first and a second communication channel and adapted to perform a transaction required by a user and identified by a plurality of transaction identification codes, a first and a second user authentication device associated to a user identification code and adapted to communicate with said terminal through respectively said first communication channel and said second communication channel comprising storage means for storing respective first and second user authentication keys, a transaction server adapted to communicate with said terminal and comprising storage means for storing, for each authentication device, respective first and second server authentication keys, wherein said first authentication keys are distinct from said second authentication keys,
said method comprises the following steps:
receiving a transaction request,
authenticating the transaction server to said first user authentication device and vice-versa by means of the first authentication keys,
authenticating the transaction server to said second user authentication device and vice-versa by means of the second authentication keys, and
performing said transaction.Join the waitlist — get patent alerts
Track US2009235074A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.